Backdoor

About “Backdoor.Win32.Emotet.bnzf” infection

Malware Removal

The Backdoor.Win32.Emotet.bnzf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.bnzf virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Emotet.bnzf?


File Info:

crc32: 5025A63F
md5: 75d1e119bc4e595c6ab4a7fded7685df
name: upload_file
sha1: 4482942b8660e0f616bf610d64f178ef58fa9e6f
sha256: f151e3a9be37003f32f0576173b038be0ad9462e1e28760a0588d925fd1223da
sha512: 2afba6d45837541f9b22edfa1223622c91637dff7ab3716c197f8673e9bc4d858fecf90bfae5d5448157116eb23dced639fbabe643cca4d932130d4710ad2c2c
ssdeep: 6144:wD9yixK0dkI6ukU1EqlhVLLiLLwLL5ZbgiUP/DRNQg3uxS/D:IrxRdbDHTC3P/NNRuxS
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor.Win32.Emotet.bnzf also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.69382
FireEyeGeneric.mg.75d1e119bc4e595c
McAfeeEmotet-FRI!75D1E119BC4E
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKDZ.69382
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_60% (W)
TrendMicroTROJ_GEN.R011C0DHC20
F-ProtW32/Kryptik.BTG.gen!Eldorado
SymantecTrojan.Emotet
APEXMalicious
KasperskyBackdoor.Win32.Emotet.bnzf
AlibabaTrojan:Win32/Emotet.39ffd3dd
ViRobotTrojan.Win32.Emotet.335872.D
TencentWin32.Backdoor.Emotet.Ajlp
Ad-AwareTrojan.GenericKDZ.69382
Comodo.UnclassifiedMalware@0
F-SecureTrojan.TR/Crypt.Agent.mxisf
DrWebTrojan.Emotet.999
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
FortinetW32/Emotet.997!tr
SophosTroj/Emotet-CKV
SentinelOneDFI – Suspicious PE
CyrenW32/Kryptik.BTG.gen!Eldorado
AviraTR/Crypt.Agent.mxisf
MAXmalware (ai score=86)
ArcabitTrojan.Generic.D10F06
ZoneAlarmBackdoor.Win32.Emotet.bnzf
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Emotet.C4179735
BitDefenderThetaGen:NN.ZexaF.34152.uqW@a8jo68ei
ALYacTrojan.GenericKDZ.69382
VBA32BScope.Trojan.Emotet
MalwarebytesTrojan.Emotet
PandaTrj/Emotet.C
ESET-NOD32a variant of Win32/Kryptik.HFMB
TrendMicro-HouseCallTROJ_GEN.R011C0DHC20
RisingBackdoor.Emotet!8.514D (CLOUD)
IkarusTrojan-Banker.Emotet
GDataTrojan.GenericKDZ.69382
AVGFileRepMalware
Cybereasonmalicious.b8660e
Paloaltogeneric.ml
Qihoo-360Generic/HEUR/QVM07.1.2C48.Malware.Gen

How to remove Backdoor.Win32.Emotet.bnzf?

Backdoor.Win32.Emotet.bnzf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment